Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.19%—Networkmanager VpncAI25/9/202630/9/2026
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
AplazadaAlta (7.8)0.19%—Networkmanager-vpncAI25/9/202630/9/2026
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN…
AplazadaAlta (7.8)0.20%—Networkmanager FortisslvpnAI25/9/202630/9/2026
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject…
AplazadaAlta (7.8)0.10%—Networkmanager SstpAI25/9/202630/9/2026
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then…
AplazadaAlta (7.8)0.14%—Networkmanager-iodineAI25/9/202630/9/2026
A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the…
Pendiente de análisisAlta (8.5)0.18%—Networkmanager-l2tpAIPppdAI23/9/202624/9/2026
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in…
Pendiente de análisisAlta (8.5)0.15%—Networkmanager-l2tpAI17/9/202623/9/2026
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers…
Pendiente de análisisAlta (7.8)0.13%—Networkmanager-l2tpAI14/9/202618/9/2026
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected…
Pendiente de análisisAlta (7.1)0.14%—NetworkmanagerAI24/8/202628/8/2026
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory,…
AplazadaAlta (7.1)0.16%—Linux-gaming PortprotonqtAIGnome NetworkmanagerAI23/7/202623/7/2026
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Pendiente de análisisMedia (6.7)0.17%—NetworkmanagerAI4/6/202625/9/2026
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an…
AplazadaBaja (3.3)0.16%—NetworkmanagerAI26/1/202630/6/2026
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
AplazadaAlta (7.8)0.46%—LibreswanAINetworkmanagerAINetworkmanager-libreswanAI22/10/202426/6/2026
A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value format, the plugin fails to escape special characters, leading the application to…
AplazadaBaja (3.1)0.45%—NetworkmanagerAI9/7/202417/6/2026
A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager would crash, leading to a denial of service.
AplazadaAlta (8.1)1.2%—LibndpAINetworkmanagerAI31/5/202417/6/2026
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
ModificadaMedia (5.5)0.26%—Gnome NetworkmanagerRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora26/5/202117/6/2026
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
ModificadaMedia (4.3)0.99%—Gnome NetworkmanagerFedoraproject Fedora8/6/202017/6/2026
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
ModificadaMedia (5.5)0.71%—Gnome NetworkmanagerDebian Linux10/3/202016/6/2026
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
ModificadaCrítica (9.8)2.2%—Networkmanager-ssh Project Networkmanager-sshDebian Linux23/2/202017/6/2026
danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.
ModificadaMedia (6.8)0.88%—Gnome NetworkmanagerOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server27/1/202016/6/2026
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
ModificadaMedia (4.4)0.43%—Gnome NetworkmanagerDebian LinuxCanonical Ubuntu LinuxOpensuse26/12/201916/6/2026
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
ModificadaAlta (7.5)2.0%—Gnome NetworkmanagerCanonical Ubuntu Linux20/3/201817/6/2026
GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates…
ModificadaMedia (6.2)0.26%—Redhat Networkmanager17/7/201717/6/2026
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and…
ModificadaMedia (5)5.1%—Gnome NetworkmanagerSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+517/11/201517/6/2026
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
ModificadaBaja (3.3)1.2%—Networkmanager Project Networkmanager16/11/201517/6/2026
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.